PT-2026-50786 · Libssh2+3 · Libssh2+3

·

CVE-2025-15661

·

Published

2026-06-18

·

Updated

2026-08-25

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libssh2 versions prior to 1.11.1 commit 2dae302
Description An out-of-bounds heap read exists in the sftp symlink() function within src/sftp.c. A malicious SSH server or man-in-the-middle attacker can disclose heap memory contents or cause a crash by sending a crafted SSH FXP NAME response. This occurs because the software fails to validate the available packet buffer size before a memcpy operation, allowing an attacker to supply a link len value larger than the actual packet data during SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target len minus one bytes.
Recommendations Update to the version containing commit 2dae302 to resolve the issue.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90936
CVE-2025-15661
ECHO-16DD-65E4-250C
JLSEC-2026-659
OESA-2026-3014
OESA-2026-3015
OESA-2026-3016
OESA-2026-3017
OESA-2026-3479
OPENSUSE-SU-2026:11109-1
OPENSUSE-SU-2026:21549-1
RHSA-2026:30132
SUSE-SU-2026:23049-1
SUSE-SU-2026:23187-1
SUSE-SU-2026:23214-1
SUSE-SU-2026:23225-1
SUSE-SU-2026:23245-1
SUSE-SU-2026:3525-1
SUSE-SU-2026:3526-1
SUSE-SU-2026:3541-1
USN-8486-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libssh2